CVE-2024-34448

HIGH8.8EPSS 0.18%

Ghost allows CSV Injection during member CSV export

Published: 5/22/2024Modified: 4/19/2025

Description

Ghost before 5.82.0 allows CSV Injection during a member CSV export.

Affected packages (2)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1HIGH8.8CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

References (4)